سياسة الخصوصية
تطبيق رحلة (Rihla) — com.rihla.app
آخر تحديث: ١٧ أغسطس ٢٠٢٦
الخلاصة
- لا نبيع بياناتك ولا نشاركها لأغراض إعلانية. لا إعلانات ولا متتبّعات.
- بياناتك محفوظة على جهازك أولاً. تُزامَن مع خادمنا لتعمل على أكثر من جهاز ولئلّا تضيع إن فقدت هاتفك.
- الشيء الوحيد الذي يخرج إلى طرف ثالث هو ما ترسله إلى «المدرّب» — وذلك لا يعمل إطلاقاً حتى تضيف مفتاحك بنفسك. تفاصيله أدناه، صريحة.
- يمكنك حذف كل شيء في أي وقت: صفحة حذف الحساب.
ما الذي نخزّنه
ما تكتبه في التطبيق. المهام والمشاريع والأهداف والنتائج الرئيسية والمعالم ومجالات الحياة والهويات والعادات وسجلّاتها وجلسات التركيز وملخّصاتها والبلوكات المجدولة والمراجعات الأسبوعية والملاحظات والبطاقات والمواد ومحتوى المعرفة وصندوق الوارد وإعدادات حسابك. هذا هو التطبيق نفسه.
حسابك. بريدك الإلكتروني، وكلمة المرور (مُعمّاة، تديرها Supabase ولا نراها أبداً)، أو اسمك المعروض إن سجّلت عبر Google.
ملفّك الشخصي، إن أدخلته. الدولة ورقم الهاتف وتاريخ الميلاد. هذه اختيارية بالكامل — والتطبيق يعمل دونها — لكن إن أدخلتها فهي تُزامَن مع خادمنا مثل بقيّة بياناتك.
أين تذهب
نسخة تبقى على جهازك (قاعدة بيانات محلية)، ونسخة تُزامَن مع خادم رحلة (Render) وقاعدة بيانات Postgres لدى Supabase. لا يحصل أحد غيرك على صلاحية قراءتها — الخادم يفصل صفوف كل مستخدم بمعرّف حسابه، ولا يُسلّم صفّاً لطلب لا يحمل رمز صاحبه.
المدرّب ومزوّد الذكاء الاصطناعي — اقرأ هذا
المدرّب متوقّف تماماً حتى تختار مزوّداً وتضيف مفتاحه بنفسك في الإعدادات. المزوّدون المتاحون اليوم: openrouter.ai، وapi.openai.com، وapi.anthropic.com، وgenerativelanguage.googleapis.com (Gemini)، أو أي خادم متوافق مع OpenAI تكتب عنوانه بنفسك. إن فعّلته، فإن ما يُرسَل إلى المزوّد الذي اخترته عند كل رسالة هو:
- إحصاءات تركيزك (الدقائق، الساعة الذهبية، التوزيع بالساعات).
- عناوين بلوكاتك الأخيرة ونصّ نيّتك المكتوبة فيها.
- عناوين مهامّك وأهدافك ومشاريعك المفتوحة.
- أسماء موادك ونصّ ملخّصاتك (الديبريف) — أي ما كتبته بنفسك عن جلساتك.
- رسائلك في المحادثة وما سبقها من ردود.
هذا محتوى حقيقي كتبته أنت، ويغادر جهازك إلى شركة أخرى تخضع لسياستها هي لا سياستنا. إن لم يعجبك ذلك فلا تضف مفتاحاً — ويبقى بقيّة التطبيق كاملاً كما هو. مفتاحك يُخزَّن في المخزن المُعمّى للجهاز ولا يُرسَل إلى خادمنا أبداً.
حالة واحدة لا يغادر فيها شيء: إن وجّهت رحلة إلى خادم متوافق مع OpenAI يعمل على جهازك نفسه (Ollama أو LM Studio أو llama.cpp)، فالطلب لا يترك جهازك أصلاً.
يطلب التطبيق كذلك قائمة النماذج المتاحة من خادمنا (GET /ai/registry). هذا الطلب عامّ ولا يحمل حسابك ولا أيّ شيء كتبته — يسأل «ما النماذج المتاحة اليوم» ولا شيء غير ذلك.
الإحصاءات المجهّلة
متوقّفة افتراضياً («ساعد في تحسين رحلة» في الإعدادات). إن فعّلتها نسجّل أحداثاً من قائمة مغلقة ومحدّدة سلفاً — «فُتح التطبيق»، «اكتمل التهيئة»، «أول جلسة تركيز» — مع وقتها ومعرّف عشوائي لا يرتبط بحسابك. لا حقول نصّية إطلاقاً، فلا يمكن بنيوياً أن يتسرّب منها شيء مما تكتبه. إيقافها يمسح ما جُمِع.
التنبيهات
كل التنبيهات تُجدوَل على جهازك محلياً. لا نستخدم خدمة إشعارات سحابية ولا نملك رمز إشعارات لجهازك.
ما لا نفعله
- لا نبيع بياناتك ولا نؤجّرها ولا نتاجر بها.
- لا إعلانات، ولا شبكات إعلانية، ولا متتبّعات طرف ثالث في التطبيق.
- لا نقرأ محتواك لتدريب نماذج.
الحذف والاحتفاظ
نحتفظ ببياناتك ما دام حسابك قائماً. عند طلب الحذف تبدأ مهلة ١٤ يوماً يُلغى الطلب خلالها بمجرّد تسجيل دخولك مرة أخرى، ثم تُحذف بياناتك وحسابك حذفاً نهائياً. التفاصيل كاملة في صفحة حذف الحساب.
الأطفال
رحلة ليست موجّهة لمن هم دون ١٣ عاماً، ولا نجمع بياناتهم عن قصد. إن علمت بحساب لطفل دون هذه السنّ راسلنا وسنحذفه.
هذا الموقع
هذا الموقع لا يطلب منك تسجيل دخول، ولا يحفظ ما تكتبه فيه، ولا يستخدم متتبّعات إعلانية. وإن أرسلت بريدك عبر نموذج «أبلغني» فهو يفتح تطبيق البريد لديك لترسل الرسالة بنفسك — لا يُخزَّن هنا شيء.
التواصل
لأي سؤال عن خصوصيتك أو بياناتك: [email protected]
Privacy Policy
Rihla (رحلة) — com.rihla.app
Last updated: 17 August 2026
The short version
- We do not sell your data or share it for advertising. No ads, no trackers.
- Your data lives on your device first. It syncs to our server so it works across devices and survives a lost phone.
- The only thing that goes to a third party is what you send to the Coach — and the Coach does nothing at all until you add your own key. Spelled out below.
- You can delete all of it, any time: account deletion.
What we store
What you write in the app. Tasks, projects, goals, key results, milestones, life areas, identities, habits and their logs, focus sessions, debriefs, scheduled blocks, weekly reviews, notes, cards, subjects, knowledge entries, your inbox, and your account settings. This is the app itself.
Your account. Your email address and password (hashed, managed by Supabase — we never see it), or your display name if you sign in with Google.
Your profile, if you fill it in. Country, phone number, and date of birth. These are entirely optional — the app works without them — but if you enter them they sync to our server along with everything else.
Where it goes
One copy stays on your device (a local database). One copy syncs to the Rihla server (Render) and a Postgres database at Supabase. Nobody else gets to read it: the server scopes every row to the account that owns it and will not hand a row to a request that does not carry that account's token.
The Coach and your AI provider — read this one
The Coach is completely off until you choose a provider and add your own API key for it in Settings. The providers available today are openrouter.ai, api.openai.com, api.anthropic.com, generativelanguage.googleapis.com (Gemini), or any OpenAI-compatible server whose address you type in yourself. If you turn it on, here is what is sent to the provider you chose on every message:
- Your focus statistics (minutes, golden hour, hourly distribution).
- The titles of your recent blocks and the intentions you wrote in them.
- The titles of your open tasks, goals, and projects.
- Your subject names and your debrief text — what you wrote about your own sessions.
- Your chat messages and the replies before them.
That is real content you wrote, leaving your device for another company under their policy, not ours. If that is not a trade you want, do not add a key — the rest of the app is unaffected and complete without it. Your key is kept in your device's encrypted storage and is never sent to our server.
One case sends nothing anywhere: if you point Rihla at an OpenAI-compatible server running on your own machine (Ollama, LM Studio, llama.cpp), the request never leaves your device.
The app also asks our server which models are currently available (GET /ai/registry). That request is public and carries neither your account nor anything you wrote — it asks “what models exist today” and nothing else.
Anonymous usage events
Off by default(“Help improve Rihla” in Settings). If you turn it on we record events from a fixed, closed list — app opened, onboarding completed, first focus session — with a timestamp and a random identifier not tied to your account. There are no free-text fields at all, so it is structurally impossible for anything you wrote to leak through it. Turning it off erases what was collected.
Notifications
All notifications are scheduled locally on your device. We do not use a cloud push service and hold no push token for your device.
What we do not do
- We do not sell, rent, or trade your data.
- No ads, no ad networks, no third-party trackers in the app.
- We do not read your content to train models.
Deletion and retention
We keep your data for as long as your account exists. When you request deletion a 14-day window begins, during which signing back in cancels it; after that, your data and your account are permanently deleted. Full detail on the account deletion page.
Children
Rihla is not directed to anyone under 13 and we do not knowingly collect their data. If you believe a child under that age has an account, email us and we will delete it.
This website
This site has no login, stores nothing you type into it, and uses no advertising trackers. If you submit your address through the “Notify me” form, it opens your own mail app so you send the message yourself — nothing is stored here.
Contact
Any question about your privacy or your data: [email protected]